News Update – The Sinkhole
TL;DRCisco pulled funding from Shadow Server, the volunteer nonprofit that sinkholed botnets like Game Over Zeus during Operation Tovar. The episode explains how sinkholes and honeypots work, and what losing Shadow Server could mean for…
Jordan & Scott discuss Shadowserver, sinkholes, and the people mapping malware .
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: It's June 2014 and Game Over is finally going down. Game Over is or was is a very sophisticated botnet run by a Russian cybercrime syndicate. It's this vast network of infected computers that the criminals controlled. We could do a whole episode about how Game Over specifically worked, but the gist is, a normal botnet is made up of a bunch of computers that have been infected with malware, reporting back to a single control point, this central server. The people who control that server control the network, but this creates a vulnerability. Because if you can take down the central control point, you can take down the whole network. Cut off the head, kill the beast. Game Over took that idea and decentralized it. It's a botnet that operates like a peer to peer network. It's a hydra in this metaphor. Chop off one head, no sweat, there are countless others. All in, Game Over infected around a million systems globally. It harvested banking information and was rented out in spam, DDoS, and online extortion campaigns that made the people responsible around a $100,000,000 as a nice round estimate. Operation Tovar was the international joint plan to take Game Over down. And June 2014 was when they pulled the pin. Taking down a vast international cybercrime network is a vast international operation. FBI, Europol, NCA, and a bunch of private companies, universities, and institutions all working together. It's easy to picture guys in trench coats confiscating gear. It's easy to picture government lawyers handing court orders to domain registrars. It's easy to imagine someone saying, go. And a bunch of people jumping into action, chopping off all the hydra's heads at once. Which leaves one last problem, What to do with this giant rotting monster corpse? In this case, the giant rotting monster corpse is its data. A bunch of data flooding out of the botnet that now has to go somewhere. The solution is something called a sinkhole and the subject of this update. In cybercrime parlance, a sinkhole is where you redirect toxic internet traffic once you've taken over control of an online criminal enterprise. It's this deep, dark hole where you can funnel the data, pick it apart, study it, and keep it quarantined. Shadow Server is a volunteer run organization that helps identify and quarantine these networks, and importantly, a really big sinkhole. They served an essential role in taking down Game Over and most other high profile botnet takedowns. They're volunteers who aid some of the largest law enforcement agencies agencies in the world in taking down organized cybercrime. And this last week, they lost their main source of funding, which is a really bad thing at an even worse time. This is Singles, Shadow Server, and how we map malware, on this hacked update. So broad strokes, how does a botnet work?
Speaker 2: How does a botnet work? Well, you have a lot of bots, computers, IoT devices with malware, etcetera. These bots are spread out around the Internet, and then usually there's a controller, something that coordinates them all. So, sends out instructions that gets, you know, propagated amongst the botnet telling all the bots what to do. Right.
Speaker 1: And what can you do with it?
Speaker 2: With a botnet? Yeah. You could do all kinds of things. DDoS, obviously, being one of the major ones. Spamming, yeah, for sure. You can change them all to to mail servers and do spam spam nets, stuff like that. But I think the major thing is just, you know, DDoS. Right. I think that's the primary use of a botnet aside from just owning a lot of computers, which I'm sure comes with a lot of, you know, power if you needed access to something inside of one of the networks that you control the computer in.
Speaker 1: Before we get to taking these things down, is this a pretty high level operation? Is this something kinda pedestrian, or is this something that takes a little bit more effort and coordination to put together? No.
Speaker 2: I think by the time you're trying to coordinate and own and control a massive botnet, you're probably this is like, you know, if this isn't your full time job, it's leaning into that.
Speaker 1: You're you're trying to take that startup and go full time
Speaker 2: with it? Precisely. Like, you're you know, you've been flirting with it at nights and stuff, working off it on the side of your desk, and now you're you're trying to go full time.
Speaker 1: Sure. Sweat equity. Yeah. Okay. So, let's flip it. I'm trying to take down a botnet. Talk me through how that process could even work. We talked a little bit in the opening story of it being kind of like a hydra. You gotta chop off all the heads at once. Take me through, like, how would someone take down a botnet?
Speaker 2: Yeah. Well, I think the and, you know, in relation to the opening story, the the the big way that they've been doing it is just identifying them, you know, seeing where they are, seeing where they're coming from, seeing, you know, what kind of botnet and malware networks these are, and then trying to figure out where they're being coordinated from. So lots of these bots know to reach back to the coordination hub and be like, hey. Give me instructions. Because as you can imagine, the controller won't know how to tell like, it won't know where all the bots get to. Right? Because this is kind of spreading like a virus. So the controller won't know who's infected. So the infected have to reach back to the controller and be like, hey. I'm infected. You control me. What should I do? So in that reach back is where a lot of this, kind of capture is happening. So they're programmed to reach back to specific, domain names. And what they're doing is they're kind of poisoning that DNS and taking control of that controller traffic, which is essentially stopping the infected controller. Does that make sense?
Speaker 1: Yeah. I think so. So I'm running one of these these networks. I've told all of these devices to report back to, you said, a DNS?
Speaker 2: Yeah. So, like, imagine you had, you know, jordansbotnet.com, and control.jordansbotnet.com was the server that you wanted all of the infected hosts to reach back to. If the entire Internet can kind of coordinate itself to poisonjordan'sbotnet.com's DNS and take control of traffic going to controller.jordan'sbotnet.com, controller.jordan'sbotnet.com. You know, if we can hijack that traffic, we can, you know, do lots of things, notably identify and kind of start to look at ways of, removing the botnet off of the infected host, but also essentially just taking away any kind of control authority from you.
Speaker 1: Okay. So step one is figuring out where all the traffic coming off these infected devices
Speaker 2: Right.
Speaker 1: Because you've basically found the hacker at that point.
Speaker 2: Yeah. So, like, just imagine, like, a like, a virus spreading between house. Once you put this virus or malware into the world, you don't know who gets infected. So you need to be able to identify what computers out there I now control. And the easiest thing to do is to have them kind of call back and say, hey, Jordan. I have it. You control me.
Speaker 1: So once I've identified the domains where all that traffic is going to, how do I take control of it so that the traffic is coming to me?
Speaker 2: Yeah. So you're essentially the you know, that's the term that you wanna start chatting about is sync holing. But but, really, what it is is poising. So you're saying, hey, DNS server. Instead of redirecting traffic to controller dot jordan's botnet dot com to this IP address, send it over to this new IP address. And this new IP address could be, you know, some massive security association, could be Yeah. Of note, I think, you know, the original story and and something that you've been reading about recently is Shadow Server, which is a big not for profit association that kinda looks to control, monitor, and shut down these massive botnets.
Speaker 1: Before you can control and monitor them, though, you have to map them out. How do you do that?
Speaker 2: Yeah. So, like, Shadow Server has a bunch of honeypots, which we've discussed in a previous episode. So they kind of have, vulnerable computers out there in the world looking to get infected with these malware things so that they can kind of stop and track and monitor the network traffic coming and going from them, which allows them to do a number of things, like fingerprint the malware so they can get a good understanding of what it is, who made it, as well as monitor the network traffic to see, you know, hey. It's creating a private VPN tunnel to this server in Russia. It turns out all of the infected hosts are probably creating that same VPN tunnel. Let's look and identify all network traffic that looks like that, and then we'll have a good understanding of who's infected.
Speaker 1: Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world. I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.
Speaker 3: You're great at protecting your data, but lots of places could still expose you to identity theft.
Speaker 2: I thought it was safe.
Speaker 3: If that happens, LifeLock gives you a US based restoration agent who will stick by your side from start to finish. Phone calls, filing documentation, preparing insurance claims, your agent handles it all. In fact, we're so confident restoration is guaranteed. Pour your money back. Isn't it nice to have someone like that on your side? Save up to 30% your first year at lifelock.com/podcast. Terms apply.
Speaker 1: What happens if we don't have something like this? Shadow servers specifically and then organizations of this class.
Speaker 2: Yeah. I think, I think what you're referring to is the fact that Cisco just pulled their primary sponsorship from Shadow Server, which is probably greatly affecting their operations. If they were to go away, then botnets would run rampant. Or or the a new company would spin up in its place. There's the you know, with opportunity or with problem comes opportunity. And, I trust that somebody will spin up to take care of that problem.
Speaker 1: So if Cisco is pulled out for whatever reason, Cisco pulled out, then, like, who funds this kind of operation?
Speaker 2: Well, just think about, like, I remember doing an economic analysis on the cost of spam, you know, in in the early two thousands, and it's massive. You know, back when spam was running rampant, just the data just the power cost, the carbon output of the power used to create and move all of the spam in the world. Like, we're talking about so much data that, you know, there's an opportunity there, just like there's an opportunity here. You know, massive botnets aren't only a threat, but they're also a major infrastructure headache. You know, if you've got millions of hosts generating tons of garbage traffic and piping that up over ISPs, over cell networks, you know, it's companies like that that are gonna then have to start paying the cost of it. So I suspect that that they'll quickly have their funding whole filled, or a company will spin up that does exactly the same thing and sells memberships to massive companies like telcos, Internet service providers, etcetera. Alright.
Speaker 1: Last question. What if we just do nothing? What if a shadow server doesn't get more funding, it goes away, and we just don't have this service anymore?
Speaker 2: It's very much, you know, a bit of an analogy for what's going on in the world right now. You know, we have a a separate type of crisis that's spreading. And if we all just ignored it, it would become paramount. So we're all trying not to ignore it and trying to do our parts to kinda control and contain and slow it down. And that's the same with this. You know? Imagine if every botnet they've ever taken offline just grew and grew and grew and grew, and they were all just compounding. Imagine the the infrastructure taxation that that would be.
Speaker 1: Thanks for listening, everybody. Up next, we're gonna jump over to Hacked After Dark, the segment of the show where we follow-up on stuff we got wrong and things people said to us on Twitter.
Speaker 2: On today's episode of Hacked After Dark, we're gonna have a response to a gentleman who tweeted at us.
Speaker 1: Twitter user at Lancaster rightfully pointed out that we in the last episode about, personal and national responses to the the COVID pandemic, we talked about what Iran was doing. Iran was just is just distributing malware. It's a separate thing. But we did irreverently ask the question, what use would location data have in a crisis like this? He points out that, Israel has been text messaging people saying, hey. You were in a physical location where someone else was that had COVID. So he rightfully points out there's a total use for having GPS data that would just didn't really occur to us when we were talking about that.
Speaker 2: I feel like we're only weeks away from all being in proximity to people that have had it.
Speaker 1: It just turns into spam at that point.
Speaker 2: It just turns into spam. It just turns into a botnet.
Speaker 4: When I found out I was gonna be a parent, I immediately felt a lot of anxiety and worry. So I went on to BetterHelp to try to look for a therapist to help me with that. My relationship with my
Speaker 2: Really getting those thoughts out to a therapist and getting feedback was just life changing.
Speaker 1: Discover what BetterHelp online therapy can do for you. Visit betterhelp.com today.